CVE-2015-7713Medium▾ SunlitOpenStack Compute (Nova) allows remote attackers to bypass intended restriction
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0.7 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
3.7%
3.7% → 3.7%
Last analysed / modified upstream
OpenStack Compute (Nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) do not properly apply security group changes, which allows remote attackers to bypass intended restriction by leveraging an instance that was running when the change was made.
nova < 2014.2.4nova >= 2015.1.0, < 2015.1.2Upgrade to a patched release:
nova 2014.2.4nova 2015.1.2Connected by shared product, vendor, weakness, or advisory.
CVE-2014-3517MediumOpenStack Compute (Nova) Exposure of Sensitive Information to an Unauthorized Actor vulnerability
CVE-2015-0259MediumOpenStack Compute (Nova) has Insufficient Verification of Data Authenticity
CVE-2021-3654Medium· 6.1Open Redirect in CPython that affects users of OpenStack Nova
CVE-2014-0167MediumOpenStack Compute (Nova) allows remote authenticated users to gain privileges via API requests
CVE-2015-3280MediumOpenStack Compute (nova) allows remote authenticated users to cause a denial of service
CVE-2013-4179MediumOpenStack Compute (Nova) vulnerable to denial of service via XML Entity Expansion attack